Your stance is leaking through the network, not through your iPhone.
Tech companies track any mobile device through telecom interconnection flaws. No iPhone patches needed.
The Citizen Lab published a report in April 2026 that for the first time links real surveillance traffic to identified operator infrastructures. The principle has been known for ten years, but the finding remains unsettling: commercial companies can locate any mobile device in the world without ever touching the device itself. Your iPhone is not at fault, and that’s precisely the problem.
The Fact
The report is called “Bad Connection”. It documents actors who track phones across over twenty countries, with one of them conducting over 1700 attacks, almost all of which are dedicated to geolocation. The described target is a “VVIP” in the Middle East, but the typical profile of this market is known: journalists, dissidents, and political figures.
The mechanism exploits the protocols that make operators communicate with each other when you roam or change antennas. They were designed in an era when a handful of national operators trusted each other implicitly. Today, there are thousands of them, and this implicit trust has become a backdoor. Three vectors coexist: SS7 on 2G and 3G, Diameter on 4G, and a variant called SIMjacker that uses a silent SMS executed on your SIM card. The Citizen Lab is categorical: these are not software bugs, but inherent flaws in global telecoms.
A crucial detail: usually, it’s not your operator selling your location. There are two markets. The first one exists: in the US, major operators have sold the location of their subscribers to data brokers, resulting in nearly $200 million in FCC fines in 2024.
The second one, the heart of this radar, is different: surveillance companies like Rayzone, Circles, or Cognyte exploit interconnection flaws by leasing legitimate access points to the global network, often via a small accomplice operator. They remotely query the network of your target, without their consent or their operator’s.
Why This Matters to You
Here’s the angle that’s unsettling. You can encrypt your messages, harden your Mac, close every macOS setting one by one, but your physical location still passes through infrastructure you don’t control, and Apple has no say in it. There’s nothing to patch on this end because it’s not a hole in iOS. It’s the architecture of the network itself.
So, most of the precautions you think of won’t help against this specific vector, and it’s better to know that than to be lulled into a false sense of security. “Hardcore” mode on your iPhone doesn’t touch an SS7 request that happens in the network. An eSIM changes the format of the card, not the protocol: as long as there’s a reachable number, you’re exposed.
Signal protects the content of your messages, not the signaling metadata that reveals where you are. Turning off data or GPS doesn’t matter either, the tracking uses the cell identifier, not your puck. The only individually effective solution is airplane mode or turning off the phone, which is hardly practical daily.
Two caveats to avoid selling you false barriers. Two-factor authentication by app has real utility, but against another risk: SMS interception of your codes, not geolocation. A dedicated number or eSIM reduces the link between your location and your real identity, but doesn’t make that number any less traceable.
The real defense is structural. It plays out with operators and regulators, with signaling firewalls that the GSMA documents in its FS.11 guide. Your security here doesn’t depend on you, but on infrastructure and a legal framework you don’t control.
Let’s be clear about the real risk: for an average person, the likelihood of being targeted remains low. This matters not because of an imminent threat to you, but because of what it reveals. Digital sovereignty doesn’t stop at the edge of your device: as long as you have a SIM card, your location circulates in a weakly constrained global network.
What You Do Now
1. Recalibrate your expectations, that’s the most useful gesture here. Keep Signal, “Hardcore” mode, and your good habits, they protect content and the device, but don’t believe they make you invisible on the network. Confusing the two is the trap.
2. For connection codes, abandon SMS and switch to app-based or hardware key two-factor authentication. It won’t protect you from geolocation, but it closes the interception of codes via the same network, and that’s a real risk to your accounts.
3. If you have a genuinely exposed profile, like a journalist, political dissident, or lawyer on a sensitive case, the only serious individual lever is physical discipline: in airplane mode or with the phone turned off, your device is no longer registered on the network, there’s nothing to locate. You only become traceable again upon re-registration. A dedicated number cloisters your identity, but remains traceable the same way.
4. For the rest, the real work isn’t on your desk. Follow the subject on the regulator side: NIS2 and ENISA set a framework, but no strong technical obligation yet forces operators to close these flaws. That’s where pressure needs to be applied.
Sources
- “Bad Connection: Uncovering Global Telecom Exploitation by Covert Surveillance Actors”, Citizen Lab, April 2026 (primary source)
- Signalling Security in Telecom SS7/Diameter/5G, ENISA (protocols deemed fundamentally flawed, EU recommendations)
- FS.11 SS7 Interconnect Security Monitoring and Firewall Guidelines, GSMA (the signaling firewall reference, industry self-regulation)
- Hacking Your Phone, 60 Minutes, CBS, 2016 (interview with Representative Ted Lieu via SS7, demonstration on an elected official)
- FCC Fines Major U.S. Wireless Carriers for Selling Customer Location Data, Krebs on Security, 2024 (the distinct market of data brokers, $200M USD in fines)
Technical terms? Check the glossary.